CVE-2026-95520: 
Linux Red Hat Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-95520 is a heap-based buffer overflow vulnerability in the rpm package manager caused by an integer overflow in the iterReadArchiveNext() function. When parsing a symlink entry in an untrusted RPM package with a RPMTAG_LONGFILESIZES value of 0xFFFFFFFFFFFFFFFF, the addition wraps to zero, resulting in a 1-byte buffer allocation; the payload's independently-controlled cpio filesize field then writes attacker-controlled data past the end of that allocation. The vulnerability is reachable via rpm2cpio, rpm2archive, and rpm -qlvp when processing untrusted packages. It was disclosed on September 29, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, Github Advisory).

Détails techniques

The root cause is an integer overflow (CWE-787: Out-of-bounds Write) in iterReadArchiveNext() at lib/rpmfi.cc:2229. When a symlink entry's RPMTAG_LONGFILESIZES header field is set to 0xFFFFFFFFFFFFFFFF, the expression xmalloc(lsize + 1) wraps to zero, allocating only a 1-byte buffer. The subsequent rpmcpioRead() call at lib/rpmfi.cc:2230 then uses the payload's independent cpio-header filesize field — entirely attacker-controlled — to copy data into that 1-byte region, enabling a heap write of attacker-chosen length and content. Exploitation requires no valid RPM signature, as rpm2cpio and rpm2archive disable header/signature checks by default; a proof of concept confirmed reliable heap-buffer-overflow WRITEs of 256, 4096, and 16,248 bytes into the 1-byte allocation using an AddressSanitizer-instrumented build (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation can result in high integrity and high availability impact, including memory corruption, potential arbitrary code execution, and application crashes. An attacker who can convince a user or automated workflow to process a crafted RPM package can corrupt heap memory, potentially leading to unauthorized code execution in the context of the invoking user. There is no confidentiality impact assessed, but the ability to modify memory and crash the process represents a significant risk in environments that automatically process RPM packages from untrusted sources (Red Hat CVE, Github Advisory).

Exploitabilité

A proof of concept was confirmed by Red Hat's security team using an AddressSanitizer-instrumented build, demonstrating reliable heap-buffer-overflow writes at multiple sizes (Red Hat Bugzilla). Exploitation requires local access and user interaction — a user or automated workflow must process the malicious RPM — but no privileges or valid package signature are required. As of the disclosure date, there is no evidence of in-the-wild exploitation, no known threat actor attribution, and the EPSS score is 0.0 (Github Advisory). The vulnerability is not listed in the CISA KEV catalog.

Étapes d’exploitation

  1. Craft a malicious RPM package: Create an RPM package containing a symlink entry with RPMTAG_LONGFILESIZES set to 0xFFFFFFFFFFFFFFFF in the package header, and set the cpio payload's filesize field to a large attacker-controlled value (e.g., 256, 4096, or 16,248 bytes) with attacker-controlled content.
  2. Deliver the package: Distribute the crafted .rpm file to the target system via any channel (e.g., a malicious repository, email attachment, or social engineering), without requiring a valid RPM signature.
  3. Trigger processing: Induce the victim user or an automated workflow to process the package using one of the vulnerable front-end commands: rpm2cpio malicious.rpm, rpm2archive malicious.rpm, or rpm -qlvp malicious.rpm.
  4. Trigger integer overflow: When iterReadArchiveNext() processes the symlink entry, the xmalloc(0xFFFFFFFFFFFFFFFF + 1) call wraps to zero, allocating a 1-byte heap buffer.
  5. Achieve heap overflow: The subsequent rpmcpioRead() call uses the cpio filesize field to write attacker-controlled data of attacker-chosen length past the end of the 1-byte allocation, corrupting heap memory.
  6. Achieve objective: Depending on heap layout and target environment, the overflow may enable arbitrary code execution in the context of the invoking user, or cause a denial of service via crash (Red Hat Bugzilla, Red Hat CVE).

Indicateurs de compromis

  • Process: Unexpected crashes or segmentation faults in rpm, rpm2cpio, or rpm2archive processes when processing RPM files from untrusted or external sources.
  • Logs: System logs (e.g., /var/log/messages, journal) showing abnormal termination of rpm-related processes with signals such as SIGSEGV or SIGABRT.
  • File System: Presence of unusual or unsigned .rpm files in temporary directories or download locations, particularly those with symlink entries and anomalous file size metadata.
  • Process: AddressSanitizer or other memory-safety tool reports of heap-buffer-overflow WRITEs originating from rpmfi.cc:2229 or rpmfi.cc:2230 in instrumented builds.

Atténuation et solutions de contournement

Red Hat has rated this issue as Moderate and a patch is in progress (tracked in Bugzilla bug 2537809). Until a fixed RPM package version is available, the primary mitigation is to avoid processing RPM packages from untrusted or unverified sources using rpm2cpio, rpm2archive, or rpm -qlvp. Organizations should enforce policies requiring RPM packages to be sourced only from trusted, signed repositories and verify package integrity before processing (Red Hat CVE, Red Hat Bugzilla).

Réactions de la communauté

Red Hat acknowledged the vulnerability and credited researcher tao pan for the report. Red Hat's product security team rated the issue as Moderate, noting that while the heap write is attacker-controlled, exploitation requires local user interaction and is not exposed as a network service (Red Hat CVE). No significant broader community or social media reactions have been observed as of the disclosure date.

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Affecté

bookworm

rpm

Affecté

sid

rpm

Affecté

trixie

rpm

Affecté

RHEL / CentOS

Affecté

RHEL 8

rpm.src

Affecté

RHEL 9

rpm.src

Affecté

RHEL 10

rpm.src

Affecté

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Linux Red Hat Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-95520HIGH7.1
  • Linux Red Hat logoLinux Red Hat
  • rpm-cron
NonNonSep 29, 2026
CVE-2026-96423MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark.src
NonNonSep 29, 2026
CVE-2026-96422MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NonNonSep 29, 2026
CVE-2026-96421MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NonNonSep 29, 2026
CVE-2026-96420MEDIUM4.7
  • Wireshark logoWireshark
  • wireshark.src
NonNonSep 29, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités